doc-prd-fixer
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands (e.g.,
mkdir -p .aidoc/review/02_PRD/<PRD-id>/) using variables derived from the artifact metadata. If the artifact ID in the audit report is maliciously crafted with shell metacharacters (e.g.,PRD-01; rm -rf /), it could lead to arbitrary command execution on the host system. - [INDIRECT_PROMPT_INJECTION]: The skill acts as a "remediation stage" that ingests untrusted data from audit reports (
.aidoc/audit/02_PRD-audit.md) and persona validation slots to modify project documentation and generate new content. - Ingestion points: Reads
.aidoc/audit/02_PRD-audit.md,verdict.json, and persona-specific JSON slots. - Boundary markers: No explicit boundary markers or "ignore previous instructions" warnings are used when processing the audit findings into the PRD content during Phase 4 (Content) or Phase 7 (Style).
- Capability inventory: The skill has high privileges including writing to the filesystem, creating/modifying directories, and dispatching other subagents.
- Sanitization: There is no evidence of sanitization or character escaping for the content being applied from the audit report to the target PRD.
- [TIME_DELAYED_CONDITIONAL]: The skill implements a break-circuit policy using
SOFT_DEADLINE(1500s) checks and wall-clock time comparisons to trigger partial timeouts and transition saga states. This is implemented for functional safety but relies on external state files (.skill-start.fixer) that could be manipulated.
Audit Metadata